Impact
The vulnerability arises from improper neutralization of user‑supplied input during web page generation, enabling DOM‑Based Cross‑Site Scripting. An attacker can inject malicious scripts that execute in the context of a victim’s browser, potentially leading to session hijacking, defacement, or arbitrary code execution. The weakness aligns with CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
The affected product is Aman: Funnel Builder by FunnelKit; all releases from the initial version through 3.13.1.2 are impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% reflects a low exploitation probability. This issue is not listed in CISA’s KEV catalog. The attack vector is likely via a user‑supplied field in the plugin’s interface, requiring victim interaction to load the malicious payload, typical of DOM‑based XSS.
OpenCVE Enrichment